# Choose who gets security alerts

Choose who gets BetterShield’s alert emails, set the weekly summary day, pause routine alerts for maintenance, mute, and test delivery.

BetterShield emails a weekly summary, and an alert straight away for anything rated high or critical. Set both under **BetterShield › Settings › Email alerts**; Quick Setup asks the same questions in its **Your site** step.

## When alerts are sent, and to whom

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| **Mute all alerts** | Stops every alert and the weekly summary. The switches below read off while muted and come back as you left them. | For a noisy spell. The Overview, the dashboard widget and the activity log show it. | Off |
| **Planned maintenance** | Pick a **Duration** (**30 minutes**, **1 hour**, **2 hours** or **4 hours**) and press **Start maintenance**. Routine instant alerts are held, and one summary goes out when it ends (if instant alerts are on). **End maintenance** ends it early. | Planned work does not flood the inbox. Critical events, decoy hits, lockdowns and changes to protections still go out, and every protection stays on. | Not running, **2 hours** preselected |
| **Where alerts go** | Type an address under **Add an address** and press **Add**, up to 5. **Remove** takes one off. Addresses need not be accounts on the site. | Alerts reach someone who will act. | The site's administration email, while none is named |
| **Send a test alert** | Sends one real "Alert delivery test" by the path every alert takes, and says whether WordPress accepted it. One every few minutes. | A broken mail setup shows up here, not as silence. | None |

Maintenance holds routine alerts such as a new administrator, a role change, or a plugin switched on with nobody signed in. Starting it is itself alerted.

**What muting does not stop:** the site is still watched and logged, and findings still open and close. Mail about a person's own account still reaches them: the link that clears a sign-in lockout, the new-network sign-in notice (where it is on), and a replacement recovery link. Alerts that queue while muted are dropped, not sent later.

Telling the Overview that a moved site is a staging copy also turns the mute on. With Ultra, muting also stops alert destinations under **Ultra › Alert channels**.

## Weekly summary and instant alerts

These are under **What is worth sending**.

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| **Send a weekly summary** | One email covering everything since the last summary. | It arrives on quiet weeks too. | On |
| **Day** | Sunday to Saturday, in the site's time zone. | | Monday |
| **Send one now** | Sends the real summary now. The next covers from this moment and still arrives on your day. | | None |
| **Email me about high and critical events as they happen** | Emails each high or critical event; everything else waits for the summary. | Some things cannot wait a week. | On |
| **Whether these are worth sending** | Alerts sent over the log's retention (30 days, or 90 with Ultra), and how many were marked unhelpful with **That alert was not worth sending** on a finding opened from an alert. | | None |

### What is sent straight away

Events the activity log tags **High** or **Critical**. The main ones:

- **Critical:** a core, plugin or other watched file altered, or new code where nothing published it; the decoy credential used or decoy URL requested; the site locked down.
- **Accounts:** an administrator or editor account created, deleted, or its email changed; on such an account, an application password created, a passkey added or removed, or two-factor turned off; a role that can manage settings or users given or taken away; a change to what a role may do; email, password and application password all changed within an hour.
- **Site settings:** site or home address, administration email, open registration or default role changed; a plugin or theme switched on with nobody signed in.
- **Protections:** two-factor or login protection loosened; a site's passkey-only roles changed; the decoy URL or credential turned off; a protection found missing on a live page; safe mode started; the lockdown lifted; maintenance started.
- **Other:** a passkey refused; an AI assistant connected; an agent changing something on its own; a quarantined file deleted; an update that did not match its published copy.

The first alert goes at once; anything in the next five minutes joins one follow-up. Nothing is sent while a visitor waits on a page; it goes with the next dashboard page, WP-CLI run or hourly task. A refused send is retried hourly, three times, then logged as "Alert could not be delivered".

## What an alert contains

Emails are plain text, sent through WordPress to the addresses above only, with the site name in brackets at the start of the subject.

- **An instant alert** names the event (or how many), lists each with its time in UTC, asks you to check each was you or someone you know, and links to the activity log.
- **The weekly summary** gives the dates covered, score, grade, open findings, what opened (with links) and resolved, activity by area, and the highest-rated open finding to look at next.
- **Every email** ends with a link to this screen.

The screen's **What an alert never contains** card states what no switch changes: no prompt to upgrade, no price and no link to buy anything; no exaggeration; and nothing leaves the site but the message itself.

## Turning alerts down

Muting, starting maintenance, switching a message off or removing an address needs a signed-in browser, and your password again if **Ask for my password before an action that removes a protection** is on (**Settings › General**). Each save is logged as "Alert settings changed", and **Put a settings change back** on **Settings › General** can restore it.

## The weekly recovery email check

**Send a weekly recovery email check** on **Protect › Recovery** sends a test to these same addresses, at most weekly. Muting, or having no address, stops it, and the readiness check says so. See [Locked out](/docs/locked-out/).

## Related

- [Install and set up](/docs/install-and-set-up/)
- [Locked out](/docs/locked-out/)
- [Activity log](/docs/activity-log/)
- [Alert channels](/docs/alert-channels/)
- [File changes](/docs/file-changes/)
- [General settings](/docs/general-settings/)
- [Multisite networks](/docs/multisite-network/)
